CSIDB logo
Incident

TriWest Healthcare Alliance

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-18 00:58

Linked entities

Victim
TriWest Healthcare Alliance
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Apr 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

TriWest Healthcare Alliance discovered a security incident in which an unauthorized individual accessed and downloaded limited protected health information, including names, Department of Defense Benefits Numbers, ZIP codes, and in a few cases Social Security numbers, addresses, and dates of birth. The breach affected approximately 11,844 TRICARE beneficiaries out of about four million covered by the managed care contractor, which notified affected individuals, offered free credit‑monitoring through Experian, engaged a forensic expert, and strengthened security controls to prevent further unauthorized access.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On April 16, 2026, TriWest Healthcare Alliance discovered that an unauthorized person had gained limited, unauthorized access to its information systems and downloaded data. The company determined that the breach may have affected protected health information of beneficiaries. On July 2, 2026, TriWest sent a notification letter to one beneficiary, which was later provided to Military Times, indicating that 11,844 beneficiaries were being warned of the data breach. In the letter, TriWest stated that it was unaware of any misuse of the compromised information and offered a free credit‑monitoring service through Experian for 24 months. The letter also provided a breach response telephone number (1‑833‑918‑1296) for reporting suspicious activity and advised beneficiaries who believe they are victims of identity theft to file a report with the Federal Trade Commission at identitytheft.gov.

The unauthorized access resulted in the acquisition of names, Department of Defense Benefits Numbers, and ZIP codes for the affected individuals. In fewer than five cases, the downloaded data also included Social Security numbers, home addresses, and dates of birth. TriWest serves as the managed care contractor for the Tricare West Region, covering approximately four million beneficiaries that include active duty service members, retirees, National Guard and Reserve members, their family members, survivors, and certain former spouses. Eligibility for these benefits is determined by the Defense Enrollment Eligibility Reporting System (DEERS). TriWest indicated that it was notifying each beneficiary about the specific types of information that were involved in their particular case.

Following the discovery, TriWest engaged a third‑party forensic expert to review exactly what information had been accessed during the incident. The company said it took immediate action to prevent any further unauthorized activity and worked with government agencies to notify affected individuals in accordance with applicable law and notification timelines. To reduce the risk of similar events, TriWest increased security controls related to password resets, strengthened its system access monitoring tools, and provided additional employee education on identifying and mitigating various types of cyber attacks.

Sources

Sources available to members: 1 source.

CSIDB